Using the Wallet Service

Authentication

Secured endpoints require a bearer token in the authorization header:
Authorization: Bearer <access_token>
The proxy validates the token in accordance with the deployment configuration (for example, following command to generate a bearer token by using the access token endpoint that is available in the Blockchain Platform Manager.
curl -sS -X POST \
  "<Access Token Endpoint – fetched from Blockchain Platform Manager>" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=password" \
  -d "client_id=<CLIENT_ID>" \
  -d "client_secret=<CLIENT_SECRET>" \
  -d "username=<USERNAME>" \
  -d "password=<PASSWORD>"
The following text shows an example response. You then use the value of access_token as the bearer token for subsequent calls.
{
  "access_token": "eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9....",
  "expires_in": 300,
  "token_type": "Bearer"
    ...
}

Authorization

UWaaS uses role-based access control. See:
User Group Group Name in OpenLDAP Description
Digital Assets Super Admin OBP_DA_SUPER_ADMIN

For governance APIs, this user is used to determine the initial Digital Asset (DA) admin user required for initiating governance process. Additional DA admins can then be added via addDaAdmin from the initial DA Admin.

The following require DA Admin group membership
  • addDaAdmin
  • removeDaAdmin
  • addUwaasKey
  • addApprovers
  • removeApprovers
  • removeUwaasKey
  • addOrUpdatePolicy

Quick Start

All calls made to local wallet endpoints require
https://rpcproxy.<InstanceName>.<InstanceDomain>/walletservice/<localwalletendpoint>

Execute your first cURL call and validate your configuration by using the following example which retrieves readiness of the application.


curl -X GET \
  "https://rpcproxy.<instancename>.<example.com>/walletservice/ready" \
  -H "Authorization: Bearer <access token>" \
  -H "Accept: application/json"